57.921 CVE seguite
783 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.921 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2011-3317 | MED 4.3 | cisco secure_access_control_server Multiple cross-site scripting (XSS) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtr78192. | 1,1% | — |
| CVE-2024-43394 | HIGH 7.5 | apache http_server Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 thro | 1,1% | — |
| CVE-2024-37325 | HIGH 8.1 | microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | 1,1% | — |
| CVE-2023-36387 | MED 5.4 | apache superset An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections. | 1,1% | — |
| CVE-2022-33632 | MED 4.7 | microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability | 1,1% | — |
| CVE-2022-30137 | MED 6.7 | microsoft service_fabric Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All S | 1,1% | — |
| CVE-2021-29798 | CRIT 9.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end databa | 1,1% | — |
| CVE-2021-22022 | MED 4.9 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor with administrative access to vRealize Operations Manager API can read any arbitrary file on server leading to information disclosure. | 1,1% | — |
| CVE-2018-9194 | MED 5.9 | fortinet fortios A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under V | 1,1% | — |
| CVE-2018-15322 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 6.0.0-6.0.1, 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.0.1-2.3.0, or Enterprise Manager 3.1.1 a BIG-IP u | 1,1% | — |
| CVE-2017-0444 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1,1% | — |
| CVE-2013-5548 | MED 4.3 | cisco ios The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec anti-replay features via IPsec tunnel traffic, aka Bug ID CSCuj47795. | 1,1% | — |
| CVE-2026-20856 | HIGH 8.1 | microsoft windows_10_1607 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 1,1% | — |
| CVE-2023-28223 | MED 6.6 | microsoft windows_server_2008 Windows Domain Name Service Remote Code Execution Vulnerability | 1,1% | — |
| CVE-2022-23281 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 1,1% | — |
| CVE-2022-20910 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20886 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20883 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20880 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20879 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2022-20873 | MED 4.7 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1,1% | — |
| CVE-2021-26623 | HIGH 7.8 | bandisoft bandizip A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function. | 1,1% | — |
| CVE-2021-1677 | MED 5.5 | microsoft azure_kubernetes_service Azure Active Directory Pod Identity Spoofing Vulnerability | 1,1% | — |
| CVE-2020-3472 | MED 5.0 | cisco webex_meetings_online A vulnerability in the contacts feature of Cisco Webex Meetings could allow an authenticated, remote attacker with a legitimate user account to access sensitive information. The vulnerability is due to improper access restrictions on users who are added within | 1,1% | — |
| CVE-2018-18688 | MED 5.3 | code-industry master_pdf_editor The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Increment | 1,1% | — |